Pimcore <10.5.22 Path Traversal via '\..\filename' in repository
CVE-2023-2984 Published on May 30, 2023

Path Traversal: '\..\filename' in pimcore/pimcore
Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22.

Github Repository NVD

Weakness Type

Path Traversal: '\..\filename'

The software uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\..\filename' (leading backslash dot dot) sequences that can resolve to a location that is outside of that directory.


Products Associated with CVE-2023-2984

Want to know whenever a new CVE is published for Pimcore? stack.watch will email you.

 

Affected Versions

pimcore/pimcore:

Vulnerable Packages

The following package name and versions may be associated with CVE-2023-2984

Package Manager Vulnerable Package Versions Fixed In
composer pimcore/pimcore < 10.5.22 10.5.22

Exploit Probability

EPSS
0.01%
Percentile
0.49%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.